Last Updated on September 8, 2026
MSPs are unusual in one way that shapes everything: your buyers look almost exactly like you. 58 per cent of UK cyber security firms have one to nine employees, and 44 per cent of micro businesses use an external provider. This is small firms selling to small firms.
Start: is anything about you independently checkable?
You are at Start if any of these is true.
- No ICO registration number on the site.
- No Cyber Essentials certificate reference, or one with no date.
- ISO claimed without naming the certification body.
- No pricing information of any kind, not even a structure.
- No response or resolution targets published.
- Your own site has no structured data and no AI crawler policy.
That last one deserves a sentence. In Whito’s July 2026 audit of 120 independent UK business websites, 92 per cent had no AI crawler policy of any kind, about 6 per cent used correct business-type structured data and one site in 120 had a hand-written llms.txt. Being an IT provider whose own site is in the failing 92 per cent is a specific and avoidable embarrassment.
The gate out of Start: a prospect can verify, without contacting you, that you are ICO registered, currently certified, and what your service tiers include.
Build: can you prove you do what you say?
The Build questions in this sector are all about evidence, because evidence is the product.
- Are response and resolution targets defined by severity and agreed in writing?
- Do you measure actual performance against them, monthly?
- Is onboarding documented so it happens the same way every time?
- Do you produce a client-facing report that a non-technical director can read?
- Do you know your own churn, and why clients leave?
The report is the underrated one. Most MSPs send a ticket summary. What a director wants is three lines: what broke, what we stopped, what you should decide. A provider that produces that monthly is very hard to replace, because the replacement will not.
The gate out of Build: you can publish last quarter’s actual performance against your own targets without wincing.
Scale: regulation, and what it does to positioning
The Cyber Security and Resilience Bill, introduced on 12 November 2025, expands the regulations to include managed service providers. We could not confirm its current stage, because the Commons Library briefing we opened was last updated on 8 July 2026, and the number of MSPs in scope is not published.
Whatever the timing, the direction is clear and it changes the market in a predictable way. A category that is currently unregulated becomes one where compliance is a threshold. Providers who already publish their registrations, certifications and performance will find that a tailwind. Providers who have sold on relationship alone will find it an audit.
The practical Scale work is unglamorous: a documented service catalogue, consistent contracts, a compliance page that is maintained rather than written once, and enough process that a second technician delivers the same service as the founder.
The channel question
Worth knowing before you budget: we found no UK source publishing MSP lead costs, directory listing fees or cost per lead on any page we could open. There is no paid MSP directory with a published rate card equivalent to what other sectors have.
The NCSC Cyber Advisor directory and the IASME certificate search are both free to appear in by virtue of certification, and IASME explicitly forbids using its search for marketing. So the channels that exist are: referral, local search, certification directories, and being genuinely useful in writing.
That last one suits this sector unusually well, because your buyers are technical enough to tell the difference between real advice and content.
Which stage are you at?
| Symptom | Stage | First move |
|---|---|---|
| Enquiries only from referral | Start | Publish registrations, certificates and service tiers |
| Losing to bigger providers on paperwork | Start to Build | Cyber Essentials, then documented service catalogue |
| Winning clients and losing them at renewal | Build | Monthly client-facing report a director can read |
| Competing only on per-user price | Build | Publish tiers by contents and response targets by severity |
| Two technicians delivering different services | Scale | Documented onboarding and a maintained compliance page |
Common questions
How should an MSP price?
In tiers defined by what is included rather than by adjective, per user per month excluding VAT, with a minimum user count and term stated. Published UK ranges run from £25 to £150 per user per month depending on publisher and inclusions, so an unqualified number tells a buyer nothing.
Is fear-based marketing effective for cyber?
Increasingly not, because the government’s own survey publishes a median breach cost of £0 with the middle half from £0 to £200. Continuity, response times, compliance evidence and insurer requirements are all measurable and all survive contact with that figure.
Where do MSP leads actually come from?
Referral, local search and certification directories, on the evidence available. We found no UK source publishing MSP lead costs or a directory rate card, and IASME’s certificate search explicitly forbids use for marketing.
The structural checks behind this research run on any website in about twenty seconds. Enter yours and read the full result on the page. Free, and we do not ask for your email.
Run the free Visibility Check
